Hi Mike,
On 10 Sep 2018, at 3:27 pm, Mike Everest <mike@duxtel.com> wrote:
Officially, our advice to all of our customers and partners is, and has always been, "never upgrade routerOS unless there is something in the new version that you need or want”
Unfortunately this isn’t great advice today, although I can understand the reasoning behind it.
That is still the case now - noting that 'fix severe security vulnerability' definitely comes in under the category of 'want or need' ;-)
Cheers!
My POV is security fixes are more need than want. In some situations you won’t want to upgrade immediately for any number of reasons. If this is the case you should perform a risk analysis and implement the necessary mitigation strategies to minimise your risk. As soon as you can upgrade, you should upgrade in my opinion. Some food for thought - From memory the average time most people take to discover they've been compromised is 18 months. Jason